This script is Copyright (C) 2010-2015 Tenable Network Security, Inc.
The remote web server is affected by several vulnerabilities.
According to its self-reported version, the web server listening on
this port is a version of Oracle iPlanet Web Server (formerly Sun Java
System Web Server) 7.0 before 7.0.9. Such versions reportedly are
affected by several vulnerabilities :
- An as-yet unspecified file disclosure vulnerability
exists in the WebDAV component. (CVE-2010-3512)
- An HTTP response splitting vulnerability exists in the
web container component due to a failure to sanitize
HTTP response headers of CR / LF characters.
- A cross-site request forgery vulnerability exists in
the management console that could allow an attacker to
stop an arbitrary server instance. (CVE-2010-3544)
- An as-yet unspecified vulnerability exists that allows
a remote attacker to impact confidentiality and
integrity via unknown vectors related to
See also :
Upgrade to Oracle iPlanet Web Server 7.0.9 or later.
Risk factor :
Medium / CVSS Base Score : 5.8
CVSS Temporal Score : 4.5
Public Exploit Available : true
Family: Web Servers
Nessus Plugin ID: 51138 ()
Bugtraq ID: 43977439844400444034
CVE ID: CVE-2010-3512CVE-2010-3514CVE-2010-3544CVE-2010-3545
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.